NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48724  CVE-2009-1448  Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.    4.3  Medium  2017-01-07  2009-04-29  View
6485  CVE-2008-6754  The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.    Medium  2017-01-03  2009-04-29  View
6500  CVE-2008-6769  Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.    Medium  2017-01-03  2009-04-29  View
6501  CVE-2008-6770  YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.    Medium  2017-01-03  2009-04-29  View
6502  CVE-2008-6771  YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function.    Medium  2017-01-03  2009-04-29  View

Page 3027 of 17672, showing 5 records out of 88360 total, starting on record 15131, ending on 15135

Actions